Aug 2026· Proceedings of the Southwest State University. Series: IT Management, Computer Science, Computer Engineering. Medical Equipment Engineering· Vol 16, pp. 167-181· 0 citations· 9 references
TL;DR
It has been found that the tools exhibit varying sensitivity to logical errors, type inconsistencies, and potentially unsafe designs, which confirms the effectiveness of using static analysis tools as a means of improving the quality and security of PHP code.
Abstract
The purpose of the research
is a comparative analysis of static PHP code analysis tools to assess their effectiveness in identifying errors, potential vulnerabilities, and typing problems in the early stages of web application development. Particular attention is paid to determining the practical applicability of the solutions under consideration in projects of various scales, as well as their impact on improving software quality, reducing the number of defects in the code and minimizing security risks.
Methods
. The study uses a comparative analysis method based on testing tools on a set of typical scenarios reflecting common errors and vulnerabilities of PHP applications. The tools were evaluated according to the criteria of completeness of error detection, accuracy of diagnosis, flexibility of rule configuration, ease of integration into the development process, productivity and resource consumption. Additionally, an analysis of documentation and configuration options was performed. All experiments were carried out repeatedly to ensure the statistical reliability of the results.
Results
. The study revealed differences in the depth of analysis, the rigor of type checking, and the mechanisms for configuring rules. It has been found that the tools exhibit varying sensitivity to logical errors, type inconsistencies, and potentially unsafe designs. Their strengths and weaknesses have been identified in the context of use in small and large projects.
Conclusion
. The results confirm the effectiveness of using static analysis tools as a means of improving the quality and security of PHP code. The choice of a specific solution should be based on the requirements of the project, the level of rigor of the analysis and the specifics of the development process. Regular use of such tools can significantly reduce the risk of defects and vulnerabilities, increasing the reliability and stability of web applications.
This article provides a comparative evaluation of the static code analysis tools CodeQL, Semgrep, and SonarQube. The architectural principles, data flow analysis mechanisms, and propagation of potentially dangerous values, as well as the effectiveness of defect detection, are compared. Accuracy, recall, harmonic measur...
M. A. Borlakova, S. Sitnikov, V. E. Vilkov· SOFT MEASUREMENTS AND COMPUT...· 0 citations
Maintaining code quality remains a significant challenge in both educational and professional software development. This paper presents the development and evaluation of static code analysis tools aimed at identifying structural issues, such as complexity, cohesion, and maintainability in C# projects. The analyzers wer...
Peter Csaszar, Máté Cserép· Proceedings of the 13th Inte...· 0 citations
Static analysis tools are widely adopted to support security vulnerability detection in modern software development, particularly when integrated into continuous integration (CI) pipelines. However, the increasing number of available tools and the operational constraints imposed by CI environments complicate tool selec...
Artur S. Farias, Rodrigo Rocha, J. Dantas· Conference on Computer Scien...· 0 citations
This study provides a comparative evaluation of static and dynamic analysis techniques applied to different malware families targeting Windows operating systems. Real-world samples were obtained from the MalwareBazaar portal and included Jigsaw ransomware, the StealC infostealer, and Remcos RAT. The results indicate th...
Dominik Tracz, D. Sawicki, Konrad Gromaszek· Journal of Computer Sciences...· 0 citations
This research investigates the possibility of replacing junior and intermediate programmers with artificial intelligence (AI)-based tools in the code generation process. To inspect the capabilities of these tools, the Qwen Coder tool was used to conduct the tests. The methodology used in the study is based on 10 tests,...
M. Pantilică, Corina Ene· Economic Insights: Trends an...· 0 citations
The experimental results show that the Cypress-based end-to-end test suite has short and stable execution times, and resilient data-cy attributes significantly reduce maintenance overhead when UI changes occur.
Quoc-Binh Nguyen, Truc-Ly Phan Nguyen, Ngoc Hong Tran et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.